🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Related Alerts and Events Timeline View

alerts events advanced search


Certain Event Details pages include a View in Timeline option, which opens a new window with filterable tables of the alerts and events related to the selected event. The Timeline of Related Alerts & Events table displays search results in two tabs, one for Alerts and one for Events.

Important

The view of the timeline differs depending on whether you have opted in to the Advanced Search Query Language. If you currently use Advanced Search Builder instead, see Timeline View Using Advanced Search Builder.

To view the Timeline of Related Alerts & Events, select View in Timeline from an Event Details page, or select Related Alerts & Events from an alert.

Timeline of Related Alerts & Events

Timeline of Related Alerts & Events

Update the Search Timeframe

You can update the search window of the Timeline of Related Alerts & Events.

  1. From the Timeline of Related Alerts & Events page, grab the handles of the timeline bar surrounding the Source Event and drag them to the time before or after you want to search.
  2. Choose Update. Secureworks® Taegis™ XDR returns the alerts and events from that window and displays them in the table below.

Change the Timeline Window Change the Timeline Window

Filter by Event Type

The Events tab view includes filters for available data types above data table. Toggle these filters to include or exclude event types from the search results table.

Data Types Filter Data Types Filter

The table of alerts and events includes the following actions that you can take:

Note

Column preferences are auto-saved to your XDR user profile.

Timeline View Using Advanced Search Builder

The following documentation applies if you have not opted in to the Advanced Search Query Language.

Data Type Button States

Data Types show four possible states:

Active

An Active Data Type button:

Tip

To move to the Advanced Search editor for a Data Type, select the (Advanced Search) icon that appears when you mouse over a Data Type button on the right-hand side. In Advanced Search you can edit the selected query, add conditions, run the query on a different timeframe, or add any other query parameter available to Advanced Search.

View in Advanced Search

View in Advanced Search

Inactive

An Inactive Data Type button:

Error

A Data Type button in the Error state:

Cancelled

A Data Type button in the Cancelled state:

Cancelled

Cancelled Event Type Filter

Data Types

The following Data Types are available in the filter:

Data Types

Data Types

 

On this page: